gradle has 5 CVEs on record between 2021 and 2023. The median CVSS is 6.9 (medium). None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.9
- Publish → KEV
- —
- Last 90 days
- 0 prev 0
Worst active — by depth score
CVE-2021-29428High· 8.8In Gradle before version 7.0, on Unix-like systems, the system temporary directory can be created with open permissions that allow multiple users to create and delete files within it49CVE-2021-32751High· 7.5Gradle is a build tool with a focus on build automation42CVE-2023-35946Medium· 6.9Gradle is a build tool with a focus on build automation and support for multi-language development38CVE-2021-29429Medium· 4.0In Gradle before version 7.0, files created with open permissions in the system temporary directory can allow an attacker to access information downloaded by Gradle22CVE-2023-44387Low· 3.2Gradle is a build tool with a focus on build automation and support for multi-language development18
gradle vulnerabilities
CVEs affecting gradle, newest first. Open any entry for full detail, references, and exploit status.
5 CVEsRSS
CVE-2023-44387Low· 3.2Gradle is a build tool with a focus on build automation and support for multi-language development
Gradle is a build tool with a focus on build automation and support for multi-language development. When copying or archiving symlinked files, Gradle resolves them but applies the permissions of the symlink itself instead of the permissi…
CVE-2023-35946Medium· 6.9Gradle is a build tool with a focus on build automation and support for multi-language development
Gradle is a build tool with a focus on build automation and support for multi-language development. When Gradle writes a dependency into its dependency cache, it uses the dependency's coordinates to compute a file location. With speciall…
CVE-2021-32751High· 7.5Gradle is a build tool with a focus on build automation
Gradle is a build tool with a focus on build automation. In versions prior to 7.2, start scripts generated by the `application` plugin and the `gradlew` script are both vulnerable to arbitrary code execution when an attacker is able to c…
CVE-2021-29428High· 8.8In Gradle before version 7.0, on Unix-like systems, the system temporary directory can be created with open permissions that allow multiple users to create and delete files within it
In Gradle before version 7.0, on Unix-like systems, the system temporary directory can be created with open permissions that allow multiple users to create and delete files within it. Gradle builds could be vulnerable to a local privileg…
CVE-2021-29429Medium· 4.0In Gradle before version 7.0, files created with open permissions in the system temporary directory can allow an attacker to access information downloaded by Gradle
In Gradle before version 7.0, files created with open permissions in the system temporary directory can allow an attacker to access information downloaded by Gradle. Some builds could be vulnerable to a local information disclosure. Remo…